Sanctus Cybersecurity Sanctus Cybersecurity

Services / Security Posture Review

Security Posture Review for Iowa Businesses

A security posture review is a practical cybersecurity assessment of how your business actually protects itself. We look at how people log in, how systems are patched and backed up, and how remote access and cloud services are set up. You get a clear picture of where you stand and a prioritized roadmap your existing team can act on.

Sound familiar?

  • Your cyber insurance renewal came with a questionnaire you couldn't confidently finish.
  • A customer or partner sent a vendor security assessment and you didn't have great answers.
  • You've heard about Iowa's HF553 safe harbor law and want to know if your security program would hold up.
  • You've never had a security evaluation and don't know where to start.

A posture review is the best starting point for any of these. It answers "where do we stand?" before you spend money on tools or deeper testing.

What we review

Access controls and MFA

How people log in, where multi-factor authentication is and isn't enforced, how admin accounts are handled, and whether former employees and unused accounts are cleaned up.

Endpoints and patch management

How laptops, desktops, and servers are kept up to date and protected, and how quickly security updates actually get applied.

Remote access and cloud services

How your team connects from outside the office through VPNs and remote access tools, and how cloud services such as Microsoft 365 are configured.

Backup and recovery

Whether your backups would survive a ransomware attack and whether you could actually restore from them when it counts.

Logging and monitoring

Whether you would notice an attack in progress. We look at what is logged, where those logs go, and whether anyone is alerted.

Measured against recognized frameworks

We evaluate your security program against the NIST Cybersecurity Framework and use recognized benchmarks, such as the CIS Benchmarks, to check how key systems and cloud services are configured. That gives you more than an opinion. It shows how your business compares to widely recognized standards, in terms insurers, customers, and auditors understand.

It also matters legally. The NIST Cybersecurity Framework is one of the frameworks named in Iowa's HF553, which gives businesses with a documented cybersecurity program an affirmative defense after a breach. Read our HF553 explainer →

How it works

  1. 1. Scoping

    We talk through your business, your systems, and what prompted the question, then agree on scope and you get a quote.

    A few days, mostly on your schedule

  2. 2. Review

    We work with you and whoever manages your IT to understand how things are set up, and check key configurations against recognized security benchmarks.

    Typically two to three weeks, including a few days of time from your IT leadership and team

  3. 3. Reporting and walkthrough

    You receive a prioritized roadmap and findings report, then we walk you through what's working, where the gaps are, and what to fix first.

    Report within a week, then a one to three hour walkthrough

What you receive

  • Executive summary you can share with leadership, your insurer, or a customer asking about your security
  • Findings report covering each area we reviewed, mapped to the NIST Cybersecurity Framework
  • Prioritized remediation roadmap of practical improvements your existing team can implement, ordered by impact
  • Results walkthrough with your leadership and IT

It's not a 200-page report that collects dust. It's a short list of what matters most, in plain English.

What a posture review costs

Security posture reviews start at $3,000. Where yours lands depends on the number of users and locations, and how many cloud services and key systems are in scope.

Many businesses follow a posture review with a vulnerability assessment or penetration test once the basics are in place.

Who it's for

  • Small and mid-sized Iowa businesses without dedicated security staff
  • Organizations that haven't had a recent security evaluation, or never have
  • Owners and managers who need honest answers for insurers, customers, or their board
  • Businesses working toward a documented security program for HF553

Reviews are performed by GPEN, GCIH, and GSEC certified consultants. We are independent. We don't manage your IT or sell security products, so the recommendations are about what your business needs, not what we sell.

Security posture review questions

How much does a security posture review cost?

Security posture reviews start at $3,000. The final price depends on the size of your environment, including the number of users and locations, and how many cloud services and key systems are in scope. We scope every review up front, so you have a quote before any work starts.

How long does a security posture review take?

Scoping usually takes a few days, mostly on your schedule. The review itself typically takes two to three weeks, including a few days of time from your IT leadership and team. The report is ready within a week of the review, and the results walkthrough usually takes one to three hours.

How is a posture review different from a vulnerability assessment or penetration test?

A posture review looks at how your security program works as a whole, including how people log in, how systems are patched, how data is backed up, and how remote access and cloud services are set up. A vulnerability assessment scans your systems for specific technical weaknesses, and a penetration test shows how far an attacker could get. If you haven't had a recent security evaluation, a posture review is usually the best place to start.

Can a posture review help with our cyber insurance questionnaire?

Yes. Insurance questionnaires ask about exactly the areas a posture review covers, such as MFA, backups, patching, and remote access. The review shows you which answers you can give honestly today, and the roadmap shows what to fix for the ones you can't.

Will a posture review help us qualify for Iowa's HF553 safe harbor?

It shows how your current security program measures up to a recognized framework and where the gaps are, which is the starting point for the documented program HF553 requires. It is not legal advice, and whether you qualify is ultimately a legal question, so involve your attorney.

What frameworks do you use?

We evaluate your security program against the NIST Cybersecurity Framework and use recognized benchmarks, such as the CIS Benchmarks, to check how key systems and cloud services are configured. Both are widely recognized, and the NIST Cybersecurity Framework is one of the frameworks named in Iowa's HF553.

Our IT is managed by an outside provider. Does that matter?

Not at all. Many small businesses work with a managed IT provider, and we can work with them directly to gather what we need. Because we are independent and don't manage IT or sell products, the review gives you an objective view of how your environment is set up.

Ready to find out where you stand?

Tell us what's prompting the question. We'll come back with a few questions of our own, not a sales pitch.

Find Out Where You Stand